{"id":"CVE-2026-58226","summary":"Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax","details":"Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding.\n\nhpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3 accumulates the integer as int + (value \u003c\u003c\u003c m), shifting by 7 more bits for each continuation octet and stopping only on a terminating octet or truncated input, never because the integer grew too large. Because BEAM integers are arbitrary precision, a run of N continuation octets builds an O(N)-bit bignum and re-adds into an ever-larger bignum on each step, so the total decoding cost is superlinear (about O(N^2)). An unauthenticated attacker who can send an HTTP/2 header block to a server using this decoder (reached through the 'Elixir.HPAX':decode/2 entry point) can supply a small header block that forces a large, attacker-controlled amount of CPU (and transient memory), a denial-of-service amplification.\n\nThis issue affects hpax from 0.1.1 before 1.0.4.","aliases":["EEF-CVE-2026-58226","GHSA-jj2p-32j7-whj2"],"modified":"2026-07-15T01:49:04.146144890Z","published":"2026-07-06T09:03:47.374Z","database_specific":{"cna_assigner":"EEF","cwe_ids":["CWE-407"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58226.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"56db437a7e2c515e3bdd770ac7947b02cd2390d0"},{"fixed":"1ba4bb2dc91e80089cf89c73970ac3ded76f17eb"}]}]},"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-58226.html"},{"type":"WEB","url":"https://github.com"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-58226"},{"type":"WEB","url":"https://repo.hex.pm"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58226.json"},{"type":"ADVISORY","url":"https://github.com/elixir-mint/hpax/security/advisories/GHSA-jj2p-32j7-whj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58226"},{"type":"FIX","url":"https://github.com/elixir-mint/hpax/commit/1ba4bb2dc91e80089cf89c73970ac3ded76f17eb"},{"type":"PACKAGE","url":"https://github.com/elixir-mint/hpax"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elixir-mint/hpax","events":[{"introduced":"9df2bf5d76e210d7da2402bce29498c5bf620ebf"},{"fixed":"8d9c57ab94651b3f076871eebe3b70fa208fe3e3"},{"fixed":"1ba4bb2dc91e80089cf89c73970ac3ded76f17eb"}],"database_specific":{"extracted_events":[{"introduced":"0.1.1"},{"fixed":"1.0.4"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v1.0.3","v1.0.2","v1.0.1","v1.0.0","v0.2.0","v0.1.2","v0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58226.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}